首页 | 本学科首页   官方微博 | 高级检索  
     

互联网BGP路由可视及安全检测技术架构与实践
引用本文:叶朝阳,沈辰,黄明庆,张士聪,刘伊莎. 互联网BGP路由可视及安全检测技术架构与实践[J]. 电信科学, 2021, 37(12): 110-120. DOI: 10.11959/j.issn.1000-0801.2021263
作者姓名:叶朝阳  沈辰  黄明庆  张士聪  刘伊莎
作者单位:浙江省新型互联网交换中心有限公司,浙江 杭州 311200;中国信息通信研究院,北京 100191;华为技术有限公司,北京 100095
摘    要:边界网关协议(border gateway protocol,BGP)是支撑互联网50年来快速发展的核心协议,因早期设计考虑不足一直存在路由劫持、路由泄露等路由安全威胁漏洞。随着互联网应用日益深入,BGP 路由安全问题逐渐引起业界重视,边界网络安全防护意义重大。提出了一种BGP路由安全检测架构,通过推理构建全球BGP路由知识库实现互联网全局路由可视性,并基于此实现路由劫持、路由泄露等路由安全事件的准实时检测。通过在杭州交换中心部署实践,证明本系统可构造较完整的互联网全局路由知识库、实现较准确和实时的BGP路由安全事件检测。

关 键 词:BGP  路由安全  路由劫持  路由泄露

Architecture and practice of BGP internet routing visibility and security detection
Chaoyang YE,Chen SHEN,Mingqing HUANG,Shicong ZHANG,Yisha LIU. Architecture and practice of BGP internet routing visibility and security detection[J]. Telecommunications Science, 2021, 37(12): 110-120. DOI: 10.11959/j.issn.1000-0801.2021263
Authors:Chaoyang YE  Chen SHEN  Mingqing HUANG  Shicong ZHANG  Yisha LIU
Affiliation:1. National (Hangzhou) New-Type Internet Exchange Point, Zhejiang 311200, China;2. China Academy of Information and Communications Technology, Beijing 100191, China;3. Huawei Technologies Co., Ltd., Beijing 100095, China
Abstract:Border Gateway Protocol (BGP) is the de facto inter-domain routing protocol of today’s global internet for exchanging routing information.However, it was supposed that all participants were reliable without generating routing security issues by mistakes or on purpose when BGP was designed 50 years ago.As Internet is getting involved in all aspects of our society, internet routing security is becoming the problems that couldn’t be ignored anymore.A general architecture was proposed which coved inference of BGP routing knowledge database and provided visibility of global internet routing.Detection of route security events such as routing hijacks and routing leaks were realized.The deployment shows that the system can provide good visibility of internet routing and precise detection of routing security events.
Keywords:BGP  internet routing security  routing hijack  routing leak  
本文献已被 万方数据 等数据库收录!
点击此处可从《电信科学》浏览原始摘要信息
点击此处可从《电信科学》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号